[imp] Spammers Using Horde/IMP to Send Bulk Message

Tim Bannister Tim.Bannister at manchester.ac.uk
Sun Sep 7 13:57:20 UTC 2008


> Does anyone has this experience?
> Spammers used the spam to ask horde/imp user to submit their account info 
> (including password)
> Somehow, user submitted.
> And spammers use this user account to send a lot of bulk messages.
> I had this experience. And seems the spammers use a programmed approach to 
> automatically fill in a dictionary-like emails addresses to the To field.
> And send each single mail to hundreds of recipient, and then repeatedly 
> sent another hundreds of recipients mails out around 10 seconds.
> 
> Does anyone has this experience? I am just asking for suggest to improve 
> in Horde/IMP webmail environment.

I hope it's obvious that we won't publish all the measures taken against
spammers as they too can read this list. An important improvement to IMP
is to integrate it with a junk mail classifier like SpamAssassin so that
users can clearly see when a message looks like junk mail. This reduces
the chance of a user being taken in. It's also important to check
outbound messages to see if they look like spam, even if all this does
is to alert someone that there may be a problem.

-- 
Tim Bannister
Email system administrator
IT Services division
The University of Manchester

t: +44 161 2757797
w: http://www.manchester.ac.uk/itservices


More information about the imp mailing list